PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65673 Microsoft CVE debrief

Microsoft Entra Connect Elevation of Privilege Vulnerability allows an authorized attacker to elevate privileges locally due to improper neutralization of special elements used in an SQL command. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Microsoft has provided an advisory and patch for this vulnerability. Affected systems require immediate attention to prevent local privilege escalation. Defenders should prioritize patching to version 2.6.84.0 or later and verify local inventory for affected versions.

Vendor
Microsoft
Product
Microsoft Entra Connect
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-10-08
Advisory published
2026-08-11
Advisory updated
2026-10-08

Who should care

Defenders responsible for Microsoft Entra Connect deployments should assess exposure and prioritize patching to version 2.6.84.0 or later. They should also verify local inventory for affected versions and monitor for local exploitation attempts. Security teams and vulnerability management teams should review the CVE record and Microsoft advisory to understand the vulnerability and its potential impact.

Why it matters

CVE-2026-65673 is a HIGH severity vulnerability in Microsoft Entra Connect that allows local privilege escalation. Defenders should prioritize patching and verify local inventory for affected versions.

  • Local privilege escalation requires verification
  • Patching is required to remediate vulnerability
  • Inventory checks are necessary to identify affected systems

Technical summary

The vulnerability exists in Microsoft Entra Connect Sync due to improper neutralization of special elements used in an SQL command. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Microsoft has provided an advisory and patch for this vulnerability, which defenders should apply to prevent local privilege escalation.

Defensive priority

Defenders should prioritize patching Microsoft Entra Connect to version 2.6.84.0 or later, and verify local inventory for affected versions.

Recommended defensive actions

  • Patch Microsoft Entra Connect to version 2.6.84.0 or later
  • Verify local inventory for affected versions
  • Monitor for local exploitation attempts

Evidence notes

The CVE record and Microsoft advisory provide details on the vulnerability, but do not specify versions or provide additional context. The vulnerability exists in Microsoft Entra Connect Sync, and defenders should verify local inventory for affected versions. The CVE Program record, NIST NVD detail page, and Microsoft advisory offer further information on the vulnerability. However, the exact scope of affected systems and potential impact are not explicitly stated.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-65673 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-65673

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-65673 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65673

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.